pith. sign in

Integrity report for Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills

A machine-verified record of the checks Pith has run against this paper: detector runs, findings, signed bundle events, and canonical identifiers.

arXiv:2605.09594

0Critical
0Advisory
4Detectors run
2026-05-20Last checked

Paper page arXiv integrity.json

Detector runs

claim_evidence completed v1.0.0 · findings 0 · 2026-05-20 07:22:01.457126+00:00
ai_meta_artifact completed v1.0.0 · findings 0 · 2026-05-19 16:39:08.785945+00:00
doi_title_agreement completed v1.0.0 · findings 0 · 2026-05-19 13:01:17.358712+00:00
doi_compliance completed v1.0.0 · findings 0 · 2026-05-19 10:07:37.809366+00:00

Findings

No public integrity findings for this paper.

Signed record

The machine-readable record for this paper lives at /pith/2605.09594/integrity.json. Pith Number bundles also include signed pith.integrity.v1 events where a Pith Number exists.